US12602483B2UtilityA1

Secure booting of channel cards using a management controller of a data processing system

Priority: Filed: Jul 26, 2024Granted: Apr 14, 2026
G06F 21/572G06F 21/575
41
PatentIndex Score
0
Cited by
39
References
20
Claims

Abstract

Methods and systems for managing operations of a data processing system are disclosed. To manage operations of the data processing system, it may be identified that firmware hosted by a channel card operably connected to the data processing system has failed verification during a secure booting procedure. A management controller of the data processing system may perform a verification procedure to obtain a channel card certificate. At least one entry may be added by the management controller to a secure booting procedure database to facilitate verification of the firmware. After the at least one entry is added, the management controller may resume the secure booting procedure. Using the at least one entry, the secure booting procedure may be completed to place the data processing system in an operable state that is conducive to providing computer-implemented services, which may then be provided.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for managing operation of a data processing system, the method comprising:
 identifying that firmware hosted by a channel card operably connected to the data processing system has failed verification during a secure booting procedure;   performing, by a management controller of the data processing system, a verification procedure to obtain a channel card certificate;   adding, by the management controller, at least one entry to a secure booting procedure database to facilitate verification of the firmware;   after the at least one entry is added, resuming, by the management controller, the secure booting procedure;   completing, using at least the at least one entry, the secure booting procedure to place the data processing system in an operable state that is conducive to providing computer-implemented services; and   providing, while the data processing system is in the operable state, the computer-implemented services.   
     
     
         2 . The method of  claim 1 , wherein the management controller is separate from and tasked with managing operation of hardware resources of the data processing system, the hardware resources comprising at least the channel card. 
     
     
         3 . The method of  claim 1 , wherein performing the verification procedure comprises obtaining identifying information for the firmware:
 via sideband channels of the data processing system, and   without the identifying information traversing an operating system of the data processing system.   
     
     
         4 . The method of  claim 1 , wherein the channel card certificate:
 is signed using a private key of a public private key pair managed by an entity with authority to authorize firmware as being trustworthy to the data processing system, and   is usable to verify, at least in part, that the firmware is safe to boot.   
     
     
         5 . The method of  claim 4 , wherein the at least one entry comprises:
 a signed hash of the firmware, the signed hash being verifiable by the data processing system using an existing trusted key.   
     
     
         6 . The method of  claim 4 , wherein the at least one entry comprises:
 a signed hash of the firmware, the signed hash of the firmware being signed using a second private key of a second public private key pair; and   the channel card certificate, the channel card certificate indicating that the second public private key pair is trustworthy.   
     
     
         7 . The method of  claim 1 , wherein completing the secure booting procedure comprises:
 obtaining, by secure booting software hosted by the data processing system, a hash of the firmware;   making a determination, using at least the hash of the firmware and the secure booting procedure database, regarding whether the firmware is verified;   in a first instance of the determination in which the firmware is verified:
 booting the firmware as a part of the secure booting procedure; and 
   in a second instance of the determination in which the firmware is not verified:
 continuing the secure booting procedure without booting the firmware. 
   
     
     
         8 . The method of  claim 1 , wherein the operable state allows application software to be run by at least an operating system of the data processing system. 
     
     
         9 . A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing operation of a data processing system, the operations comprising:
 identifying that firmware hosted by a channel card operably connected to the data processing system has failed verification during a secure booting procedure;   performing, by a management controller of the data processing system, a verification procedure to obtain a channel card certificate;   adding, by the management controller, at least one entry to a secure booting procedure database to facilitate verification of the firmware;   after the at least one entry is added, resuming, by the management controller, the secure booting procedure;   completing, using at least the at least one entry, the secure booting procedure to place the data processing system in an operable state that is conducive to providing computer-implemented services; and   providing, while the data processing system is in the operable state, the computer-implemented services.   
     
     
         10 . The non-transitory machine-readable medium of  claim 9 , wherein the management controller is separate from and tasked with managing operation of hardware resources of the data processing system, the hardware resources comprising at least the channel card. 
     
     
         11 . The non-transitory machine-readable medium of  claim 9 , wherein performing the verification procedure comprises obtaining identifying information for the firmware:
 via sideband channels of the data processing system, and   without the identifying information traversing an operating system of the data processing system.   
     
     
         12 . The non-transitory machine-readable medium of  claim 9 , wherein the channel card certificate:
 is signed using a private key of a public private key pair managed by an entity with authority to authorize firmware as being trustworthy to the data processing system, and   is usable to verify, at least in part, that the firmware is safe to boot.   
     
     
         13 . The non-transitory machine-readable medium of  claim 12 , wherein the at least one entry comprises:
 a signed hash of the firmware, the signed hash being verifiable by the data processing system using an existing trusted key.   
     
     
         14 . The non-transitory machine-readable medium of  claim 12 , wherein the at least one entry comprises:
 a signed hash of the firmware, the signed hash of the firmware being signed using a second private key of a second public private key pair; and   the channel card certificate, the channel card certificate indicating that the second public private key pair is trustworthy.   
     
     
         15 . A data processing system, comprising:
 a processor; and   a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for managing operation of a data processing system, the operations comprising:
 identifying that firmware hosted by a channel card operably connected to the data processing system has failed verification during a secure booting procedure; 
 performing, by a management controller of the data processing system, a verification procedure to obtain a channel card certificate; 
 adding, by the management controller, at least one entry to a secure booting procedure database to facilitate verification of the firmware; 
 after the at least one entry is added, resuming, by the management controller, the secure booting procedure; 
 completing, using at least the at least one entry, the secure booting procedure to place the data processing system in an operable state that is conducive to providing computer-implemented services; and 
 providing, while the data processing system is in the operable state, the computer-implemented services. 
   
     
     
         16 . The data processing system of  claim 15 , wherein the management controller is separate from and tasked with managing operation of hardware resources of the data processing system, the hardware resources comprising at least the channel card. 
     
     
         17 . The data processing system of  claim 15 , wherein performing the verification procedure comprises obtaining identifying information for the firmware:
 via sideband channels of the data processing system, and   without the identifying information traversing an operating system of the data processing system.   
     
     
         18 . The data processing system of  claim 15 , wherein the channel card certificate:
 is signed using a private key of a public private key pair managed by an entity with authority to authorize firmware as being trustworthy to the data processing system, and   is usable to verify, at least in part, that the firmware is safe to boot.   
     
     
         19 . The data processing system of  claim 18 , wherein the at least one entry comprises:
 a signed hash of the firmware, the signed hash being verifiable by the data processing system using an existing trusted key.   
     
     
         20 . The data processing system of  claim 18 , wherein the at least one entry comprises:
 a signed hash of the firmware, the signed hash of the firmware being signed using a second private key of a second public private key pair; and   the channel card certificate, the channel card certificate indicating that the second public private key pair is trustworthy.

Join the waitlist — get patent alerts

Track US12602483B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.